Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-08-26 CVE-2020-14160 Server-Side Request Forgery (SSRF) vulnerability in Thecodingmachine Gotenberg
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.
network
low complexity
thecodingmachine CWE-918
7.5
2021-08-24 CVE-2021-28627 Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery.
network
low complexity
adobe CWE-918
8.8
2021-08-20 CVE-2020-25353 Server-Side Request Forgery (SSRF) vulnerability in Rconfig 3.9.5
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.
network
low complexity
rconfig CWE-918
6.5
2021-08-20 CVE-2021-22255 Server-Side Request Forgery (SSRF) vulnerability in Baserow
SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server network exposed over HTTP by inserting an internal address.
network
low complexity
baserow CWE-918
6.5
2021-08-16 CVE-2021-37711 Server-Side Request Forgery (SSRF) vulnerability in Shopware
Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL.
network
low complexity
shopware CWE-918
8.8
2021-08-13 CVE-2021-37353 Server-Side Request Forgery (SSRF) vulnerability in Nagios XI Docker Wizard
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
network
low complexity
nagios CWE-918
critical
9.8
2021-08-05 CVE-2021-32603 Server-Side Request Forgery (SSRF) vulnerability in Fortinet Fortianalyzer and Fortimanager
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests.
network
low complexity
fortinet CWE-918
6.5
2021-07-30 CVE-2021-20788 Server-Side Request Forgery (SSRF) vulnerability in Groupsession products
Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote authenticated attacker to conduct a port scan from the product and/or obtain information from the internal Web server.
network
low complexity
groupsession CWE-918
4.3
2021-07-28 CVE-2020-4974 Server-Side Request Forgery (SSRF) vulnerability in IBM products
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF).
network
low complexity
ibm CWE-918
6.3
2021-07-22 CVE-2021-26699 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite 7.10.3/7.10.4
OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter component when the .png extension is used.
network
low complexity
open-xchange CWE-918
5.4